Description
- Open redirect
- Stored XSS
- Verbose error message (stack trace)
- Verbose error message (SQL error)
Verbose Error Message - Stack Trace
Steps to Reproduce:
- Directly browse to edit profile page
- Error should come up with verbose stack trace
Verbose Error Message - SQL Error
Steps to Reproduce:
Page Settings > Design > Save Changes
- Intercept HTTP POST request and place single quote to "pTemplateID"
- Verbose SQL error message would occur
Open Redirect
Steps to Reproduce:
- Login to application
- Click to "Edit This Page" button
- Intercept HTTP GET request
- Enter relevant domain as value for "redirect" parameter
Stored XSS
Steps to Reproduce:
- Edit page
- Add HTML widget and drag it to the page
- Add XSS payload in the HTML editor window
"><iframe src="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==">
Conclusion
- Had lots of fun fuzzing the application
- Until next Friday!
- Cheers
No comments:
Post a Comment